
Privacy & responsible recovery
Your business data
Recover stores account information, customer records you import, generated messages, approvals, outcomes, and activity metadata. Raw upload files are discarded after parsing. You control what you upload and who you contact. Do not upload card data, government identifiers, health information, or unnecessary sensitive notes.
Account activity and signup sources
We store a bounded source label from your signup link (such as LinkedIn or referral), your account creation time, and your most recent successful sign-in. Only designated app administrators can view account emails and summary workspace usage. The owner dashboard excludes imported customer records and message contents. Source labels are self-reported link metadata, not verified attribution. We do not use tracking pixels or browser storage for this feature, and do not track anonymous visits. Account metadata is retained until account deletion; activity logs follow workspace retention settings.
Providers & data transfers
Mock mode sends nothing externally. Configured email, WhatsApp, CRM, accounting, billing, and AI providers process only the data needed for the requested action. Optional model generation sends customer name and opportunity details to the configured gateway. Review provider terms, locations, and transfer arrangements before using real customer data.
Retention, export, and deletion
Workspace owners can export their data, select 30, 90, 180, or 365 days of retention, and explicitly purge expired records in Settings. Retention is based on import date and is not an automatic background deletion schedule. Deleting the workspace removes its application records. Provider logs, payment records, and infrastructure backups follow separate retention schedules.
Regional launch responsibilities
USA: assess applicable state privacy obligations and commercial-email rules. Canada: assess PIPEDA, relevant provincial laws, and CASL consent requirements. Saudi Arabia: assess PDPL, applicable regulations, and cross-border transfer requirements. These notes are a starting point, not a claim of compliance or legal advice. See the project security document for official sources and the launch checklist.
Human approval
No recovery communication is sent without approval of the saved message. Provider acceptance does not prove delivery. Recorded recovery is entered by your team and is not independently reconciled to bank deposits.
Contact
The deploying business must publish its legal identity, privacy contact, processor disclosures, terms, and support address before accepting public customers.